<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>IsItPatched — ColdFusion security feed</title>
    <link>https://isitpatched.com/coldfusion</link>
    <atom:link href="https://isitpatched.com/feed/product/coldfusion.xml" rel="self" type="application/rss+xml" />
    <description>Security alerts for ColdFusion: newly-exploited CVEs and end-of-life events from IsItPatched.</description>
    <language>en</language>
    <copyright>Compiled by IsItPatched (isitpatched.com) from NVD, CISA KEV, EPSS and endoflife.date.</copyright>
    <generator>IsItPatched (https://isitpatched.com)</generator>
    <docs>https://www.rssboard.org/rss-specification</docs>
    <ttl>15</ttl>
    <image>
      <url>https://isitpatched.com/icon-192.png</url>
      <title>IsItPatched — ColdFusion security feed</title>
      <link>https://isitpatched.com/coldfusion</link>
    </image>
    <lastBuildDate>Tue, 16 Jun 2026 22:43:51 GMT</lastBuildDate>
    <item>
      <title>ColdFusion: CVE-2024-20767 (High, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2024-20767</link>
      <guid isPermaLink="false">coldfusion|CVE-2024-20767</guid>
      <description>Severity: High (CVSS 7.4) · Improper access control · Actively exploited (CISA KEV) · EPSS 99%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Mon, 18 Mar 2024 12:15:06 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2023-44353 (Critical)</title>
      <link>https://isitpatched.com/cve/CVE-2023-44353</link>
      <guid isPermaLink="false">coldfusion|CVE-2023-44353</guid>
      <description>Severity: Critical (CVSS 9.8) · Insecure deserialization · EPSS 80%</description>
      <category>Critical</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Fri, 17 Nov 2023 14:15:21 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2023-44352 (Medium)</title>
      <link>https://isitpatched.com/cve/CVE-2023-44352</link>
      <guid isPermaLink="false">coldfusion|CVE-2023-44352</guid>
      <description>Severity: Medium (CVSS 6.1) · Cross-site scripting (XSS) · EPSS 85%</description>
      <category>Medium</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Fri, 17 Nov 2023 14:15:21 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2023-38205 (High, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2023-38205</link>
      <guid isPermaLink="false">coldfusion|CVE-2023-38205</guid>
      <description>Severity: High (CVSS 7.5) · Improper access control · Actively exploited (CISA KEV) · EPSS 100%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Thu, 14 Sep 2023 08:15:07 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2023-38203 (Critical, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2023-38203</link>
      <guid isPermaLink="false">coldfusion|CVE-2023-38203</guid>
      <description>Severity: Critical (CVSS 9.8) · Insecure deserialization · Actively exploited (CISA KEV) · Ransomware-linked · EPSS 97%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Thu, 20 Jul 2023 16:15:12 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2023-29300 (Critical, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2023-29300</link>
      <guid isPermaLink="false">coldfusion|CVE-2023-29300</guid>
      <description>Severity: Critical (CVSS 9.8) · Insecure deserialization · Actively exploited (CISA KEV) · Ransomware-linked · EPSS 100%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Wed, 12 Jul 2023 16:15:11 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2023-29298 (High, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2023-29298</link>
      <guid isPermaLink="false">coldfusion|CVE-2023-29298</guid>
      <description>Severity: High (CVSS 7.5) · Improper access control · Actively exploited (CISA KEV) · EPSS 100%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Wed, 12 Jul 2023 16:15:11 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2023-26360 (High, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2023-26360</link>
      <guid isPermaLink="false">coldfusion|CVE-2023-26360</guid>
      <description>Severity: High (CVSS 8.6) · Improper access control · Actively exploited (CISA KEV) · EPSS 97%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Thu, 23 Mar 2023 20:15:15 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2023-26359 (Critical, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2023-26359</link>
      <guid isPermaLink="false">coldfusion|CVE-2023-26359</guid>
      <description>Severity: Critical (CVSS 9.8) · Insecure deserialization · Actively exploited (CISA KEV) · EPSS 18%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Thu, 23 Mar 2023 20:15:15 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2022-38421 (High)</title>
      <link>https://isitpatched.com/cve/CVE-2022-38421</link>
      <guid isPermaLink="false">coldfusion|CVE-2022-38421</guid>
      <description>Severity: High (CVSS 7.2) · Path traversal · EPSS 79%</description>
      <category>High</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Fri, 14 Oct 2022 20:15:13 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2022-38418 (Critical)</title>
      <link>https://isitpatched.com/cve/CVE-2022-38418</link>
      <guid isPermaLink="false">coldfusion|CVE-2022-38418</guid>
      <description>Severity: Critical (CVSS 9.8) · Path traversal · EPSS 80%</description>
      <category>Critical</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Fri, 14 Oct 2022 20:15:12 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2018-15961 (Critical, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2018-15961</link>
      <guid isPermaLink="false">coldfusion|CVE-2018-15961</guid>
      <description>Severity: Critical (CVSS 9.8) · Unrestricted file upload · Actively exploited (CISA KEV) · EPSS 100%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Tue, 25 Sep 2018 13:29:01 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2018-4939 (Critical, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2018-4939</link>
      <guid isPermaLink="false">coldfusion|CVE-2018-4939</guid>
      <description>Severity: Critical (CVSS 9.8) · Insecure deserialization · Actively exploited (CISA KEV) · EPSS 63%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Sat, 19 May 2018 17:29:01 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2017-3066 (Critical, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2017-3066</link>
      <guid isPermaLink="false">coldfusion|CVE-2017-3066</guid>
      <description>Severity: Critical (CVSS 9.8) · Insecure deserialization · Actively exploited (CISA KEV) · EPSS 91%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Thu, 27 Apr 2017 14:59:00 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2013-0632 (Critical, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2013-0632</link>
      <guid isPermaLink="false">coldfusion|CVE-2013-0632</guid>
      <description>Severity: Critical (CVSS 9.8) · CWE-276 · Actively exploited (CISA KEV) · EPSS 94%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Thu, 17 Jan 2013 00:55:01 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2013-0631 (High, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2013-0631</link>
      <guid isPermaLink="false">coldfusion|CVE-2013-0631</guid>
      <description>Severity: High (CVSS 7.5) · Actively exploited (CISA KEV) · EPSS 66%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Wed, 09 Jan 2013 01:55:03 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2013-0629 (High, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2013-0629</link>
      <guid isPermaLink="false">coldfusion|CVE-2013-0629</guid>
      <description>Severity: High (CVSS 7.5) · Actively exploited (CISA KEV) · EPSS 66%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Wed, 09 Jan 2013 01:55:03 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2013-0625 (Critical, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2013-0625</link>
      <guid isPermaLink="false">coldfusion|CVE-2013-0625</guid>
      <description>Severity: Critical (CVSS 9.8) · Improper authentication · Actively exploited (CISA KEV) · EPSS 94%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Wed, 09 Jan 2013 01:55:00 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2010-2861 (Critical, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2010-2861</link>
      <guid isPermaLink="false">coldfusion|CVE-2010-2861</guid>
      <description>Severity: Critical (CVSS 9.8) · Path traversal · Actively exploited (CISA KEV) · Ransomware-linked · EPSS 100%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Wed, 11 Aug 2010 18:47:51 GMT</pubDate>
    </item>
    <item>
      <title>ColdFusion: CVE-2009-3960 (Medium, exploited)</title>
      <link>https://isitpatched.com/cve/CVE-2009-3960</link>
      <guid isPermaLink="false">coldfusion|CVE-2009-3960</guid>
      <description>Severity: Medium (CVSS 6.5) · Actively exploited (CISA KEV) · Ransomware-linked · EPSS 90%</description>
      <category>Exploited</category>
      <source url="https://isitpatched.com/feed/product/coldfusion.xml">IsItPatched</source>
      <pubDate>Mon, 15 Feb 2010 18:30:00 GMT</pubDate>
    </item>
  </channel>
</rss>